CVE-2023-41740: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-41740?
CVE-2023-41740 is an improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in the cgi component in Synology Router Manager (SRM) before version 1.3.1-9346-6.
How does CVE-2023-41740 impact Synology Router Manager (SRM)?
CVE-2023-41740 allows remote attackers to read specific files in Synology Router Manager (SRM) through unspecified vectors.
What is the severity of CVE-2023-41740?
CVE-2023-41740 has a severity rating of 5.3, which is classified as medium.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-41740?
The CWE ID for CVE-2023-41740 is CWE-22.
How can I fix CVE-2023-41740?
To fix CVE-2023-41740, update Synology Router Manager (SRM) to version 1.3.1-9346-6 or later. Refer to the Synology Security Advisory Synology_SA_23_10 for more information.